logo

Microsoft Defender for Office 365 now blocks email bombing attacks

ID: 204ab195-80d2-53cf-b147-7bba69101b43

STIX ID: report--204ab195-80d2-53cf-b147-7bba69101b43

Feed Name: Bleeping Computer

Date Published: 2025-06-30

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft introduced a new ‘Mail Bombing’ detection in Defender for Office 365 that automatically identifies high-volume email flooding attacks and routes them to Junk by default, with visibility in Threat Explorer, Email entity pages, and Advanced Hunting during a June–July 2025 rollout. The report highlights how email bombing is used by groups like BlackBasta, a 3AM ransomware affiliate, and actors linked to FIN7 to overwhelm users and defenses, enabling social engineering and remote access via tools such as AnyDesk or Windows Quick Assist, often preceding malware and ransomware deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.